Privacy · Pre-release draft
Privacy Policy
A transparent account of the personal data the current Enternica product processes—and the decisions still required before launch.
Last reviewed: 9 October 2026
Placeholder values
Launch details awaiting approval
- Legal operator
- Pending founder confirmation
- Registered address
- Pending founder confirmation
- Privacy and legal contact
- Pending founder confirmation
- Effective date
- Not yet effective
Scope and current status
This notice describes personal-data processing visible in the current Enternica product and repository. It is designed around Indonesia'sLaw No. 27 of 2022 on Personal Data Protection and Government Regulation No. 71 of 2019 on Electronic Systems and Transactions.
The identity and address of the production data controller have not yet been approved for publication. That information and a working privacy-rights contact are mandatory launch blockers.
Data the product processes
Depending on how you use Enternica, the product can process:
- Account data: name, email, authentication provider, password credentials managed by the authentication provider, phone contact, verification state, and session records.
- Professional data: profile details, role, services, public media, official links, representation, and authority records.
- Inquiry and event data: event requirements, schedule, location, messages, availability, and proposal history.
- Booking and agreement data: accepted terms, revisions, designations, consent evidence, signatures, generated documents, delivery records, and completion state.
- Finance records: invoices, bank-transfer destination snapshots, payment evidence, review state, and related references. The current product does not store card credentials.
- Technical data: necessary cookies, identifiers, request and security information, and records needed to prevent unauthorized access and diagnose service failures.
Where data comes from
Data comes from you, other authorized participants in a shared booking or professional workspace, your chosen sign-in provider, and technical records created when the product operates. Users must not submit another person's data without authority and an appropriate lawful basis.
Purposes and lawful bases
Enternica processes data to:
- create and secure accounts and verify trusted identities;
- provide profiles, inquiries, bookings, agreements, and invoices;
- deliver files and records to authorized participants;
- prevent fraud, abuse, unauthorized access, and data loss;
- diagnose failures and maintain product integrity; and
- meet applicable contractual and legal obligations.
The intended bases include steps requested before a contract, performance of a contract, compliance with legal obligations, explicit consent where required, and proportionate legitimate interests balanced against user rights. Each production purpose must be mapped to its final basis before launch.
Visibility and sharing
Published professional profiles and selected media are public. Private inquiries, bookings, agreements, invoices, payment evidence, contact data, and authority records are intended only for authenticated users with the required relationship or authority.
Data can be processed by infrastructure providers needed to operate the service. The current implementation uses Supabase for authentication and database services, Cloudinary for configured media and restricted-document delivery, and Google when a user chooses Google sign-in. Final production email and hosting providers remain to be approved and must be added to this notice.
International data transfers
External infrastructure providers may process data outside Indonesia. Production regions, transfer recipients, and applicable safeguards have not yet been confirmed. Enternica must document and validate an appropriate transfer basis before hosted public deployment.
Retention and deletion
Data should be retained only while needed for the stated purpose, security, contractual records, dispute handling, or a legal retention obligation, then deleted or anonymized where appropriate.
The product does not yet expose a complete retention schedule, self-service export, or account-deletion workflow. Exact periods for accounts, inquiries, agreements, financial records, security logs, backups, and uploaded files must be approved and published before launch.
Security
The current implementation uses role and relationship checks, least-privilege database policies, restricted delivery links, verified authentication states, and security-focused regression tests. No system is perfectly secure. Production incident response, monitoring, backups, and restore evidence remain separate launch requirements.
Your privacy rights
Subject to applicable law and identity verification, individuals can have rights to information, access, correction, a copy or transfer of their data, withdrawal of consent, restriction or objection, termination of processing, deletion, and complaint or compensation. Some requests can be limited where another person's rights, security, active disputes, contracts, or legal retention duties apply.
A recorded electronic or non-electronic request channel and response procedure must be approved before public launch. The product must not imply that an unavailable self-service control has already fulfilled a legal request.
Children and protected users
Enternica is not currently designed as a service for children. The minimum user-age rule, parental or guardian authorization process, and any handling of data about child performers require a specific founder and legal decision before such use is permitted.
Data incidents
If a personal-data protection failure occurs, the production operator must investigate, contain, document, and provide notices required by applicable law. Indonesian Law No. 27 of 2022 includes a written notice deadline of no later than 3 × 24 hours for qualifying failures. A tested production incident-response owner and contact path remain launch requirements.
Contact and policy changes
A verified privacy contact, operator legal name, registered address, and escalation route must be published here before this notice becomes effective. No address is fabricated in this pre-release draft.
Material changes should identify their effective date and be communicated appropriately. A new purpose or processor must be assessed and documented before related processing starts.